Your bank set a deadline. Here is what a PCI DSS compliance audit really involves.
A PCI DSS compliance audit explained in plain words, with the prices published rather than hidden behind a form. Then, if you want it, a written estimate for getting ready, usually inside one business day.
Read this first. A formal PCI DSS compliance audit can only be performed by a Qualified Security Assessor, or QSA. We are not a QSA and we do not perform audits. What we do is get you ready for one, so that when your QSA arrives you pass. If you need a QSA, we will introduce you to one.
Five questions, about a minute. No phone number asked for, and no sales call.
What a PCI DSS compliance audit costs
Published US market ranges for a PCI DSS compliance audit in 2026. Almost nobody puts these on a page, but here they are.
The assessor's fee is only part of a PCI DSS compliance audit. Readiness and remediation are usually the larger half, because that is where the actual work happens.
Price my own scopeThe teams we get through a PCI DSS compliance audit
Finance, engineering and compliance teams use us to arrive at their PCI DSS compliance audit prepared, so the assessor finds a tidy environment instead of a scramble.
Logos are the property of their respective owners.
What a PCI DSS compliance audit actually is
Your bank sent a letter and it used a frightening phrase. So here is what a PCI DSS compliance audit actually means, without any jargon.
A PCI DSS compliance audit is an independent check of whether your business handles credit card data safely. So think of it like a health inspection for a restaurant, except the thing inspected is payment data rather than a kitchen.
The rules being checked are called PCI DSS. They were written by the card companies, and there are twelve of them. So a PCI DSS compliance audit works through those twelve, asks for evidence, and writes up what it finds.
The part that surprises most people is who does the inspecting. Only a Qualified Security Assessor can perform a formal PCI DSS compliance audit and sign the report your bank accepts. That is a licensed role, and it is not something any consultant can do, although plenty imply otherwise.
Your PCI DSS compliance audit now includes 51 new requirements
The deadline for PCI DSS v4.0.1 was 31 March 2025. It has passed. Any assessment from that date onward has to include the new requirements, so a business that has not looked at this since 2024 is almost certainly non-compliant right now.
Every script on your payment page
You now have to know exactly which scripts run on the page where customers type their card number, authorise each one, and prove none of them changed without you noticing.
What a PCI DSS compliance audit now checks for tampering
You need something actively monitoring that payment page for unexpected changes. A firewall does not cover this, although a lot of businesses assume it does.
Multi-factor on everything
Multi-factor authentication is now required for all access into the cardholder data environment, not just for administrators coming in from outside.
Two of those requirements were removed from SAQ A entirely. So if you have been relying on the shortest self-assessment form and assuming your payment provider covers scripts, that assumption is worth checking before your next PCI DSS compliance audit.
Who is allowed to perform a PCI DSS compliance audit
This is the most useful thing to understand before you spend money on a PCI DSS compliance audit. That is, it tells you what you are buying and from whom.
| Document | Plain words | Who may sign it |
|---|---|---|
| Report on Compliance | The full audit report, often hundreds of pages. | A QSA only. Internal assessors may sign for merchants, but never for service providers. |
| Attestation of Compliance | The short summary you actually hand to your bank. | A QSA plus your executive, or your executive alone on the self-assessment route. |
| Self-Assessment Questionnaire | A yes and no form you complete yourself. | You do. A consultant may help you understand it, but your executive signs it. |
| ASV scan report | A quarterly scan of anything of yours facing the internet. | Only a vendor on the official Approved Scanning Vendor list. |
So the honest summary is short. In a PCI DSS compliance audit a QSA assesses and signs, while everyone else prepares, fixes and documents. Anyone who blurs that line is either careless or hoping you will not ask.
What happens during a PCI DSS compliance audit
A PCI DSS compliance audit runs in six stages. Most businesses fail not because they are insecure, but because they were not ready for stage three.
Scoping your PCI DSS compliance audit
Working out which systems, people and processes touch card data. Because everything inside that boundary gets tested, this stage decides most of what a PCI DSS compliance audit costs.
Evidence gathering
Screenshots, configurations, logs, policies and records. This is where unprepared businesses lose weeks, since nobody collected anything in advance.
The PCI DSS compliance audit itself
Your assessor works through the requirements, interviews staff and examines what you handed over. They test, but they do not fix.
Findings
A list of anything that does not meet a requirement. However, a finding is not automatically a failure, provided you can close it in time.
Remediation
You fix what was found and produce fresh evidence. So the shorter this list is, the sooner the whole thing ends.
Closing the PCI DSS compliance audit
Your QSA writes the report and signs the attestation. That signed page is the thing your bank actually wanted all along.
What drives the price of a PCI DSS compliance audit
Nobody in this market publishes what a PCI DSS compliance audit costs. However, we think that is the wrong way round, so here is both the range and the reason behind it.
| Driver | How much it moves the price |
|---|---|
| Transaction volume | Between two and ten times. It sets your merchant level, and therefore whether a QSA is required at all. |
| Which form applies | Between three and eight times. The shortest self-assessment is a few pages, but the longest runs past 300 questions. |
| Size of the card environment | Up to five times. Every extra system inside the boundary is another thing to test. |
| How you take payment | Up to three times. A hosted checkout is cheapest, while phone orders are the most expensive. |
| Network separation | Up to double. Without it, your whole network is inside the boundary. |
| First time or renewal | Year two typically costs 40 to 60 percent of year one, since the documentation already exists. |
Six signs you are not ready for a PCI DSS compliance audit
Each of these will cost you time in a PCI DSS compliance audit. Moreover, several of them will fail you outright.
No script inventory before your PCI DSS compliance audit
You cannot list every script running on your payment page. That is Requirement 6.4.3, and it is now mandatory.
Nothing watching for changes
No monitoring alerts you when that payment page is modified. Requirement 11.6.1 asks for exactly this.
Multi-factor only for admins
Requirement 8.4.2 now applies to all access into the card environment, so partial coverage is a finding.
Treating the PCI DSS compliance audit as annual
One misconfigured port breaks it. Because v4.0.1 expects continuous evidence, an annual scramble no longer passes.
Nobody can define the scope
If two people in your business draw the boundary differently, your PCI DSS compliance audit will find that immediately.
Evidence lives in people's heads
If the proof exists but nobody has collected it, you will spend the assessment window hunting screenshots instead of passing.
What we do, and where your PCI DSS compliance audit begins
Most firms are vague about this. However, we would rather put it in a table, because the boundary is the whole point.
What Ashcroft does
- Gap analysis against every applicable requirement
- Scoping, and reducing that scope where we can
- Remediation planning and hands-on implementation
- Policies, procedures and the evidence package
- Helping you understand and complete your own questionnaire
- Introducing you to independent QSA firms, and coordinating with them
What Ashcroft never does
- Perform the audit, or anything we would call an assessment
- Sign a Report on Compliance or issue an attestation
- Describe ourselves as a QSA, because we are not one
- Run the quarterly scans, which need an approved vendor
- Certify or validate anything, since that is a QSA function
- Promise you will pass. Nobody honest can promise that.
How we prepare you for your PCI DSS compliance audit
Five stages of preparation before your PCI DSS compliance audit begins. So you always know which one you are in.
Scope and shrink
We map every path card data takes through your business, then look for ways to make that map smaller. Because scope drives cost, this stage usually pays for itself.
Gap analysis against every PCI DSS compliance audit requirement
We compare what you have against every requirement that applies to you, including the v4.0.1 additions, and hand you a prioritised list rather than a wall of text.
Remediation
We fix things with your team rather than handing over a report and leaving. So the awkward items get closed instead of postponed.
The evidence your PCI DSS compliance audit needs
We assemble the documentation your assessor will ask for, organised the way they expect it. This is where most of the assessment week is normally lost.
QSA handover
We work alongside your chosen assessor, or introduce you to one, and stay available while your PCI DSS compliance audit runs.
Where your PCI DSS compliance audit support comes from
You contract with Ashcroft Payment Security wherever your engagement runs. Because the work is coordinated across US and UK hours, questions raised in the morning are usually answered the same working day.
Boston
Massachusetts, United States
1 Beacon StreetBoston, Massachusetts
United States
Eastern Time · US engagements
London
United Kingdom
169 PiccadillyLondon W1J 9EH
United Kingdom
Greenwich Mean Time · UK and EU engagements
PCI DSS compliance audit questions buyers ask first
Do you perform the PCI DSS compliance audit yourselves?
No. Only a QSA can perform a formal PCI DSS compliance audit and sign the report your bank will accept. We are not a QSA. We prepare you for the assessment, and we can introduce you to independent QSA firms when you are ready.
Can you certify us as compliant?
No, and nobody outside a QSA can. Certifying and validating are assessor functions. What we can do is close the gaps that would otherwise fail you, so the assessor finds very little to write up.
We use Stripe, so are we already compliant?
Not quite. Your processor's compliance covers their systems, but it does not cover your checkout page, your scripts, your logs or your staff. Requirements 6.4.3 and 11.6.1 are specifically yours. Using a hosted checkout shrinks the work a great deal, although it does not remove it.
PCI is not a law, so can anyone actually make us do it?
It is not a statute, but it is in the contract you signed with your bank to accept cards. Break that contract and your bank can fine you, raise your fees, or stop you processing altogether. In practice that is as binding as a law.
How much will our PCI DSS compliance audit cost?
A typical Level 2 e-commerce merchant spends between $85,000 and $190,000 across the whole first year, with the QSA fee being only part of it. Send us five answers and we will give you a range for your own scope, usually within one business day.
Can you guarantee we pass our PCI DSS compliance audit?
No, and walk away from anyone who says otherwise. Your assessor reaches their own independent conclusion. What we commit to is that the gaps we find are closed and the evidence is ready before they arrive.
What was the March 2025 deadline?
That was when the 51 future-dated requirements in PCI DSS v4.0.1 became mandatory. It has passed. So any assessment from that date has to include them, and businesses that have not revisited their controls since 2024 are usually non-compliant without realising it.
Why is there no phone number on this site?
Because five written questions tell us more about your scope than a discovery call would, and it also respects your time. Answer them and you get a written range back rather than a calendar link.
Price your PCI DSS compliance audit prep in five questions
These five answers are what anyone needs to estimate PCI DSS compliance audit preparation. So we can send a range without putting you through a call first.











